Superhuman software security. The only security product software engineers love.

New York
Pinned Tweet
Almanax has been acquired by @depthfirstlabs!
.@AlmanaxAI is joining @depthfirstlabs! @mmwtsn and I started the company two years ago because we'd grown tired of seeing weekly multi-million-dollar hacks destroying blockchain companies and stealing people's life savings. We believed the industry needed to move from annual security audits and pentests to continuous ones, and that AI would eventually get us there. We were among the first to see the potential of AI in cyber and build new solutions in this space. When we started, most security teams told us our product wouldn't work, they didn’t need more findings, and they didn't trust AI to be good. But then we saw how the commercial tools our clients were using were missing many of the vulnerabilities we were detecting, while producing an absurd number of false positives. We ended up working with some of the largest blockchain companies: Solana, Stellar, Aptos, Privy and Bridge (now part of Stripe), DFNS, Algorand. When people didn't believe, we showed them results: we found issues in Vitalik's code (arguably one of the best software engineers on Earth), ethically disclosed hundreds of vulnerabilities (to Ripple, Coinbase, Fireblocks), and won security competitions against thousands of researchers. As we progressed, we realized that while crypto companies were among the most vulnerable (exploits directly steal money), the problem was widespread beyond blockchain. The rise of vibe coding created an enormous new attack surface and new models and harnesses were detecting vulnerabilities that had gone unnoticed in software packages for decades, some of which power most of today’s internet. The time between CVE public disclosure and first confirmed in-the-wild exploitation has dropped from 2.3 years in 2018 to eight hours today. This and the release of frontier cyber models shook the industry. So we expanded our product support to languages and tech stacks used widely by enterprises. But the scale of what needs to be done requires more than what any one small team can do alone We believe joining forces with depthfirst will significantly accelerate our shared vision to secure the world’s software. depthfirst is already swinging at the same future we set out to build, with the team and the resources to lead the way. Their bet, and now ours, is that the next major security platform will be in product security. As their investor @arshammem put it, every category eventually gets one company whose name becomes synonymous with it: Palo Alto Networks for the network, CrowdStrike for the endpoint, Wiz for the cloud. Product and application security, notwithstanding many attempts, is still left without a crowned victor. We think depthfirst can be that company. Thanks to our great team, investors, and customers who believed in us and shared our vision of the world. Our ambition is now even bigger and we’re excited to build that future with @qasimmith, @andreamichi, Daniele, and the entire @depthfirstlabs team.
1
2
7
1,035
Almanax retweeted
Today, @washingtonpost covered critical vulnerabilities @depthfirstlabs found in TikTok. These vulnerabilities allowed hackers to access anything on a user’s device that TikTok itself could access, including the camera, microphone, payment information, photos, and the user’s entire TikTok account. Read more in the thread 🧵
14
81
361
101,005
.@hosseeb is doing great job bringing awareness to the compute arms race between attackers and defenders and the new equilibrium this will generate. Recommended watch
.@hosseeb on why beating North Korea's hackers now comes down to who can afford the most compute: "If the attackers are spending 500 bucks, and good guys are spending maybe a couple bucks, they're like, oh, I just wanna check and see if there's any low-hanging fruit. Otherwise I'm not gonna use this code if I can tell it's obviously busted. So they spend a couple dollars worth of compute, and they say, ah, it looks good enough. It's a well-funded project. It's open source. Yeah, I guess I'll use it." "But North Korea is spending 500 bucks, 1,000 bucks, 2,000 bucks just grinding and grinding and grinding, running multiple agents overnight trying to find an attack." "That means that no matter how many good people are spending $2 worth of GLM compute on you, they will never be able to find the depth of the tree that North Korea is searching for. None of the normal users will ever get there, which means it's only really on the company." "The company is the only party that can coordinate enough compute to be able to actually expand the search space enough to out search an attacker." "But it does mean that attackers have the same problem. So if North Korea and Russia and China are all trying to hack your protocol, but they all spend, let's say, $5,000 each, if you spend $10,000 you will actually find everything that they can find and more." "Which in that sense, it benefits defenders over attackers in the long run, because the company can actually outspend any individual attacker in principle, and that used to be not sufficient defense in the old model because of the fact that attackers were uncorrelated with each other." @dragonflyvc
2
13
972
Almanax retweeted
Today we're announcing dfs-large1, our newest cybersecurity model that achieves best-in-class performance on vulnerability detection tasks. Besides frontier AI labs, only a handful of companies have built specialized models that reach the state of the art in their domain. We're proud to be the first to do it for cybersecurity. dfs-large1 is built on GLM-5.2 and post-trained with reinforcement learning inside depthfirst's security infrastructure. We evaluated it on depthfirst-bench, our benchmark of long-horizon vulnerability discovery across complex repositories, where it achieves best-in-class performance. Training improvements have not plateaued yet and we expect additional performance gains as we continue training. A huge thank you to @FireworksAI_HQ for being an outstanding training partner. Their infrastructure enabled us run large-scale reinforcement learning efficiently and iterate much faster. dfs-large1 is now in preview within the @depthfirstlabs platform
28
41
208
60,401
It is time for the security industry to graduate from CyberGym Level 1. CyberGym has been one of the most impactful cybersecurity benchmarks since its launch in June 2025. Compared to prior benchmarks, it represented a jump in scale and a step in the right direction for the industry. At launch, the task was hard for everyone. The top agent-model combinations hit only about 20%, while the best single model at the time, Claude Sonnet 4, reached a mere 17.9%. In April 2026, Mythos shocked the industry by scoring 83.1%. The top of the leaderboard has since compressed, with multiple companies now showing performance above 90%. Eventually every public benchmark saturates, and Level 1 is now there. Building benchmarks is hard, and public ones can have short half lives once they are widely adopted. While CyberGym was a great step forward for the industry, it is time to graduate from CyberGym Level 1 as the primary measure of cyber capability, in favor of newer benchmarks. @hohnjeyer and I wrote about it in the blog post below.
5
10
62
10,548
When I heard the numbers for the first time I thought I misheard. We’re doing a lot of work to help secure open-source projects and committed $5M in credits to the cause. Open-source maintainers are often the last line of defense for infrastructure that millions of people depend on. We believe every defender should have access to frontier-level security.
We discovered 105 vulnerabilities across 34 projects in Ruby, some of which had remained undetected for more than 15 years. Collectively, these projects have been downloaded more than 8.6 billion times. The GitLab Remote Code Execution announced by @depthfirstlabs last week emerged from this broader investigation into the Ruby ecosystem. depthfirst's platform validated these vulnerabilities at scale and generated clear evidence for maintainers. Its supply chain module recorded affected versions as dependency issues, and automatically recommended appropriate upgrades. This research was part of the Open Defense Initiative, a $5m commitment in depthfirst credits to help OSS maintainers secure their projects. Read more about it in the comments. At @depthfirstlabs, some of the brightest minds in security, engineering, and AI are working together to build the OS for security. We're hiring across the board - join us to build a generational company with incredible people and secure the world's software. Full Report: depthfirst.com/research/behi…
3
1
14
1,560
Almanax retweeted
We achieved a GitLab RCE in its default configuration by chaining two memory corruption bugs in Oj found autonomously by depthfirst. Read the technical details and demo POC in the comments.
We successfully achieved an RCE on GitLab in its default configuration. Historically, most GitLab RCEs have lived in the web or application-logic layers. This time, guided by the @depthfirstlabs spirit, we went deeper: into the low-level gem dependency chain beneath GitLab. The result? By sending crafted JSON data, we could exploit memory-corruption vulnerabilities buried deep in that chain and take control of the GitLab application server. @depthfirstlabs brings together some of the smartest people, and is building the best security AI agent. Follow our work, and come join us! Read more about this in the comment...
4
10
65
10,233
Almanax retweeted
We successfully achieved an RCE on GitLab in its default configuration. Historically, most GitLab RCEs have lived in the web or application-logic layers. This time, guided by the @depthfirstlabs spirit, we went deeper: into the low-level gem dependency chain beneath GitLab. The result? By sending crafted JSON data, we could exploit memory-corruption vulnerabilities buried deep in that chain and take control of the GitLab application server. @depthfirstlabs brings together some of the smartest people, and is building the best security AI agent. Follow our work, and come join us! Read more about this in the comment...
16
138
689
102,206
Perhaps the very first case of an AI model “escaping containment” and hacking a real company’s production infrastructure
July 2026 may end up being remembered as one of the most important days in cybersecurity and human history. Last week, @huggingface was attacked by a fully autonomous system. Today’s update from @OpenAI that this attack was caused by their testing further reinforces something that’s becoming hard to ignore: autonomous cyber capabilities are advancing faster than anyone predicted. Sure - the frontier labs have added classifiers that prevent cyber use but 1) these classifiers are not foolproof and 2) open weight models are already close to the frontier level: there is no putting this genie back in the bottle. We are at a crossroads today. I wrote about this incident and what needs to happen in the following post (link in comments).
1
1
5
370
I'll be at Black Hat and in Vegas in a couple of weeks with other folks from the @depthfirstlabs team and we're hosting multiple events with our friends at Tracebit, Axonis, World Wide Technology, and EverSec Group. Come say hi at our booth or join us for one of our events. Link to RSVP in the comments
1
1
8
286
Almanax retweeted
depthfirst 🤝 Almanax
Thank you @Nasdaq for featuring the acquisition of @AlmanaxAI by @depthfirstlabs in Times Square! A pretty great way to say goodbye to New York before moving back to San Francisco. depthfirst is growing quickly and hiring across the company. If there's a role you’re interested in, send me a DM!
2
6
161
388,286
Thank you @Nasdaq for featuring the acquisition of @AlmanaxAI by @depthfirstlabs in Times Square! A pretty great way to say goodbye to New York before moving back to San Francisco. depthfirst is growing quickly and hiring across the company. If there's a role you’re interested in, send me a DM!
3
7
34
467,608
@AlmanaxAI saw where security was heading before most people believed it. finding vulns in code written by some of the best engineers alive, disclosing to Ripple, Coinbase, and Fireblocks along the way. now joining @depthfirstlabs to build the next great security platform. nitter.net/Hadronfc/status/207156…
Big one for @AlmanaxAI! One of the sharpest teams we've watched work, and they're chasing something the whole space actually needs. Excited to see what you guys cook up at @depthfirstlabs. go build 🫡
2
3
220
Big one for @AlmanaxAI! One of the sharpest teams we've watched work, and they're chasing something the whole space actually needs. Excited to see what you guys cook up at @depthfirstlabs. go build 🫡
.@AlmanaxAI is joining @depthfirstlabs! @mmwtsn and I started the company two years ago because we'd grown tired of seeing weekly multi-million-dollar hacks destroying blockchain companies and stealing people's life savings. We believed the industry needed to move from annual security audits and pentests to continuous ones, and that AI would eventually get us there. We were among the first to see the potential of AI in cyber and build new solutions in this space. When we started, most security teams told us our product wouldn't work, they didn’t need more findings, and they didn't trust AI to be good. But then we saw how the commercial tools our clients were using were missing many of the vulnerabilities we were detecting, while producing an absurd number of false positives. We ended up working with some of the largest blockchain companies: Solana, Stellar, Aptos, Privy and Bridge (now part of Stripe), DFNS, Algorand. When people didn't believe, we showed them results: we found issues in Vitalik's code (arguably one of the best software engineers on Earth), ethically disclosed hundreds of vulnerabilities (to Ripple, Coinbase, Fireblocks), and won security competitions against thousands of researchers. As we progressed, we realized that while crypto companies were among the most vulnerable (exploits directly steal money), the problem was widespread beyond blockchain. The rise of vibe coding created an enormous new attack surface and new models and harnesses were detecting vulnerabilities that had gone unnoticed in software packages for decades, some of which power most of today’s internet. The time between CVE public disclosure and first confirmed in-the-wild exploitation has dropped from 2.3 years in 2018 to eight hours today. This and the release of frontier cyber models shook the industry. So we expanded our product support to languages and tech stacks used widely by enterprises. But the scale of what needs to be done requires more than what any one small team can do alone We believe joining forces with depthfirst will significantly accelerate our shared vision to secure the world’s software. depthfirst is already swinging at the same future we set out to build, with the team and the resources to lead the way. Their bet, and now ours, is that the next major security platform will be in product security. As their investor @arshammem put it, every category eventually gets one company whose name becomes synonymous with it: Palo Alto Networks for the network, CrowdStrike for the endpoint, Wiz for the cloud. Product and application security, notwithstanding many attempts, is still left without a crowned victor. We think depthfirst can be that company. Thanks to our great team, investors, and customers who believed in us and shared our vision of the world. Our ambition is now even bigger and we’re excited to build that future with @qasimmith, @andreamichi, Daniele, and the entire @depthfirstlabs team.
3
2
10
1,317
Almanax retweeted
@AlmanaxAI is joining @depthfirstlabs! The window to get AI security right is narrowing. As models get more capable and the attack surface expands, defenders need to move faster than the threat. When we met @francescpicc and team, it was clear they had been working through the same hard problems and shared our view of where security is going. We’re thrilled to welcome them onboard.
1
4
17
1,388
Almanax retweeted
Welcome to the team @AlmanaxAI - Great to have you onboard
@AlmanaxAI is joining @depthfirstlabs! The window to get AI security right is narrowing. As models get more capable and the attack surface expands, defenders need to move faster than the threat. When we met @francescpicc and team, it was clear they had been working through the same hard problems and shared our view of where security is going. We’re thrilled to welcome them onboard.
1
1
15
826
.@AlmanaxAI is joining @depthfirstlabs! @mmwtsn and I started the company two years ago because we'd grown tired of seeing weekly multi-million-dollar hacks destroying blockchain companies and stealing people's life savings. We believed the industry needed to move from annual security audits and pentests to continuous ones, and that AI would eventually get us there. We were among the first to see the potential of AI in cyber and build new solutions in this space. When we started, most security teams told us our product wouldn't work, they didn’t need more findings, and they didn't trust AI to be good. But then we saw how the commercial tools our clients were using were missing many of the vulnerabilities we were detecting, while producing an absurd number of false positives. We ended up working with some of the largest blockchain companies: Solana, Stellar, Aptos, Privy and Bridge (now part of Stripe), DFNS, Algorand. When people didn't believe, we showed them results: we found issues in Vitalik's code (arguably one of the best software engineers on Earth), ethically disclosed hundreds of vulnerabilities (to Ripple, Coinbase, Fireblocks), and won security competitions against thousands of researchers. As we progressed, we realized that while crypto companies were among the most vulnerable (exploits directly steal money), the problem was widespread beyond blockchain. The rise of vibe coding created an enormous new attack surface and new models and harnesses were detecting vulnerabilities that had gone unnoticed in software packages for decades, some of which power most of today’s internet. The time between CVE public disclosure and first confirmed in-the-wild exploitation has dropped from 2.3 years in 2018 to eight hours today. This and the release of frontier cyber models shook the industry. So we expanded our product support to languages and tech stacks used widely by enterprises. But the scale of what needs to be done requires more than what any one small team can do alone We believe joining forces with depthfirst will significantly accelerate our shared vision to secure the world’s software. depthfirst is already swinging at the same future we set out to build, with the team and the resources to lead the way. Their bet, and now ours, is that the next major security platform will be in product security. As their investor @arshammem put it, every category eventually gets one company whose name becomes synonymous with it: Palo Alto Networks for the network, CrowdStrike for the endpoint, Wiz for the cloud. Product and application security, notwithstanding many attempts, is still left without a crowned victor. We think depthfirst can be that company. Thanks to our great team, investors, and customers who believed in us and shared our vision of the world. Our ambition is now even bigger and we’re excited to build that future with @qasimmith, @andreamichi, Daniele, and the entire @depthfirstlabs team.
6
9
51
6,554
Almanax retweeted
If you’re a project building on Solana, DM us
Reminder that Solana builders are eligible for a free year of @AlmanaxAI - Detection - Threat Modeling - PR Reviews - Custom Rules - Agents Learning - AI Triage - Auto-Patching
2
2
6
827
Almost 75% of exploited vulnerabilities are now zero-days, meaning that an exploit occurred before disclosure. That number was at around 50% last year, and 16% in 2018
9
19
70
12,427